MCP 2026-07-28: From Stateful Sessions to Web-Native Agent Infrastructure
Return to AI Harness.
The 2026-07-28 Model Context Protocol specification is an architectural reset rather than a routine feature release. MCP moves from a bidirectional, session-oriented protocol toward stateless, self-contained request/response semantics that fit ordinary HTTP infrastructure.
The practical result is a protocol that is easier to scale horizontally, route through gateways, cache, authorize, and operate as shared production infrastructure.
What changed
Stateless protocol core
- The
initialize/notifications/initializedhandshake andMcp-Session-Idheader are removed. - Every request carries its protocol version and client capabilities in
_meta; clients should also identify themselves per request. - Servers must implement
server/discoverto advertise supported versions, capabilities, and identity. Clients may call it before other requests, but discovery is not a required first step. - Any request can reach any server instance behind a normal round-robin load balancer without shared transport-session storage.
- Applications may still keep cross-call state, but servers should mint explicit handles and clients should pass those handles as normal tool arguments.
Multi Round-Trip Requests
Multi Round-Trip Requests (MRTR) replace server-initiated roots/list, sampling/createMessage, and elicitation/create requests that previously depended on a held-open bidirectional stream.
When a server needs user input, confirmation, or another client-provided value during a call, it returns:
resultType: "input_required"- one or more
inputRequests
The client obtains the answers and retries the original request with inputResponses. Ordinary completed results now carry resultType: "complete".
HTTP-native routing and caching
- Streamable HTTP POST requests must expose the MCP method through
Mcp-Method;tools/call,resources/read, andprompts/getalso expose their name or URI throughMcp-Name. - Gateways, WAFs, rate limiters, and authorization layers can therefore govern MCP traffic without parsing JSON-RPC request bodies.
tools/list,prompts/list,resources/list,resources/read, andresources/templates/listresults now includettlMsandcacheScope.- Servers should return
tools/listresults in a deterministic order, reducing repeated discovery traffic and stabilizing upstream LLM prompt caches.
Notifications and long-running tasks
- Opt-in change notifications move to a single
subscriptions/listenstream. - Request-scoped progress and log notifications remain on the response stream of the request they describe.
- Tasks leave the experimental core and become the official
io.modelcontextprotocol/tasksextension. - The redesigned Tasks extension uses polling through
tasks/get, addstasks/updatefor client input, and supports durable task handles.
Authorization hardening
- Clients must validate an authorization response’s
issvalue against the recorded issuer before redeeming the code. - Client credentials are bound to the authorization server that issued them and must not be reused across issuers.
- Dynamic Client Registration clients must declare the appropriate
application_type, fixing common redirect URI failures for desktop and CLI clients. - Dynamic Client Registration is formally deprecated in favor of Client ID Metadata Documents, while remaining available during the compatibility period.
Deprecations
The specification introduces a formal feature lifecycle with a minimum twelve-month deprecation window.
New implementations should not adopt:
- Roots
- Sampling
- Logging
- legacy HTTP+SSE transport
The suggested direction is explicit tool or resource parameters instead of Roots, direct model-provider integration instead of Sampling, OpenTelemetry or standard process logging instead of MCP Logging, and Streamable HTTP instead of HTTP+SSE.
Engineering interpretation
This release makes MCP look less like a persistent agent socket and more like conventional web infrastructure:
- Horizontal scaling becomes the default deployment model. Stateless requests can be sent to any healthy instance without sticky sessions or shared protocol state.
- State becomes model-visible and auditable. Explicit handles reveal cross-call dependencies that were previously hidden in the transport layer.
- Governance moves closer to existing enterprise controls. Header-level method and name metadata lets gateways enforce tool-specific routing, authorization, metering, and audit policy.
- Caching becomes part of the protocol contract. Deterministic lists and cache hints reduce discovery overhead and protect prompt-cache stability.
- Interactive tools require retry-safe design. Because MRTR resumes by retrying the original request, a server should not perform irreversible side effects before required input is supplied. Tool handlers need clear idempotency boundaries.
- Observability must follow requests and explicit task handles. Session-centric dashboards and correlation logic should migrate toward trace context, request IDs, task handles, and application-level state identifiers.
Migration checklist
- Inventory dependencies on
initialize,Mcp-Session-Id, sticky sessions, and shared transport state. - Replace implicit session data with explicit, scoped handles passed in tool arguments.
- Implement
server/discoverand populate per-request protocol, capability, and identity metadata. - Add
resultTypehandling and implement MRTR retry behavior. - Define idempotency rules for calls that can return
input_requiredor be retried after a broken response stream. - Add and validate routing policy for
Mcp-Methodon every POST andMcp-Namewhere the protocol requires it. - Implement cache hints and deterministic ordering for list and resource responses.
- Migrate long-running work to the Tasks extension and notifications to
subscriptions/listen. - Bind stored OAuth credentials to their issuer and plan the move from Dynamic Client Registration to Client ID Metadata Documents.
- Plan removal of Roots, Sampling, Logging, and HTTP+SSE before the deprecation window closes.
- Upgrade against the matching Tier 1 SDK migration guide; TypeScript, Python, Go, and C# support the new specification, while Rust support launched in beta.